Authentication Bypass Vulnerability in Woffice by Envato Security Team
CVE-2024-43234
9.8CRITICAL
Summary
The CVE-2024-43234 vulnerability is classified as an authentication bypass vulnerability that affects the Woffice theme developed by the Envato Security Team. This flaw enables attackers to bypass security measures, allowing unauthorized access to sensitive areas without proper authentication. The vulnerability impacts versions of Woffice ranging from n/a to 5.4.14, putting users at risk of potential account takeovers and data compromises. It is crucial to address this vulnerability promptly by updating to the latest version of Woffice to mitigate any associated risks.
Affected Version(s)
Woffice <= 5.4.14
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)